Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCyberSec First Responder (CFR)

Domain 2Objective 1

Objective 2.1 Analyze Logs for Signs of Attack. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 7)

Part of the 2.0 Analyze Attacks on Computing Environments domain, which accounts for 20% of the CYBERSEC-FIRST-RESPONDER exam.

38questions here
8free pages
10concepts
20%of the exam

Questions 31–35

  1. 31foundation · easy

    Why is it important to consider the context of a log event, such as the affected asset and user, when assessing its severity?

    Select an answer first
  2. 32foundation · easy

    Which of the following is an example of an indicator of compromise (IOC) that might be found in a threat intelligence feed?

    Select an answer first
  3. 33foundation · easy

    When analyzing a log event, what does the 'severity' or 'criticality' level indicate?

    Select an answer first
  4. 34foundation · easy

    Which technique is most effective for reducing log noise in a SIEM?

    Select an answer first
  5. 35expert · hard

    A security analyst is correlating events across multiple logs. They see a phishing email reported by a user, followed by a successful login from a new device, and then data exfiltration to an external IP. Which correlation would best confirm the attack chain?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.